1. Please
open Notepad- Click Start , then Run
- Type notepad.exe in the Run Box.
2. Now
copy/paste the entire content of the codebox below into the Notepad window:
KillAll::
File::
c:\windows\system32\TDSSmtve.dat
Folder::c:\program files\Trymedia
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.
3.
Save the above as
CFScript.txt
4. Physically disconnect from the internet.
5. Now
STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
6. Then
drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.
7. After reboot, (in case it asks to reboot), please post the following reports/logs into your next replyafter you
re-enable all the programs that were disabled during the running of ComboFix:
Please take note:
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
====
Download
SDFix
and save it to your desktop.
Please then reboot your computer in
Safe Mode by doing the
following :
- Restart your computer
- After hearing your computer beep once during startup, but before the
Windows icon appears, tap the F8 key continually;
- Instead of Windows loading as normal, a menu with options should appear;
- Select the first option, to run Windows in Safe Mode, then press "Enter".
- Choose your usual account.
- In Safe Mode, right click the SDFix.zip folder and choose Extract
All,
- Open the extracted folder and double click RunThis.bat to
start the script.
- Type Y to begin the script.
- It will remove the Trojan Services then make some repairs to the
registry and prompt you to press any key to Reboot.
- Press any Key and it will restart the PC.
- Your system will take longer that normal to restart as the fixtool
will be running and removing files.
- When the desktop loads the Fixtool will complete the removal and
display Finished, then press any key to end the script and load
your desktop icons.
- Finally open the SDFix folder on your desktop and copy and paste the
contents of the results file Report.txt back onto the forum with
a new HijackThis log.
Please post the SDFix log within CODE Tags.